Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

131–140 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#131
post #77

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

The more I read people against GDPR the more I get the feeling they're the same kind of people behind mail based scams.

The more noise I hear those who work in "ad tech" and other fields that have been marching towards the destruction of privacy making about GDPR, the more confident I become that it might actually help.

Re: Facebook urged to make GDPR its “baseline standard” globally

#132
post #49

Maybe it’s my American DNA but I don’t want European laws. I don’t suspect this to be a popular sentiment here.

Why the distinction? A good law is still a good law, regardless of its origin.

Same is true of a bad law as well. GDPR has good intent, but it’s not clear that it’s a good law yet.

Re: Facebook urged to make GDPR its “baseline standard” globally

#133
post #46

Earlier quoted context omitted.

How is the country/continent of origin of a regulation that is entirely in your best interest of any relevance?

> How is the country/continent of origin of a regulation that is entirely in your best interest of any relevance? Laws carry their culture. GDPR is, from an American perspective, an overworked mess designed to support a big bureaucracy. This side of the Atlantic, we'd do something slimmer, more reliant on privately-funded cases (and regulatory complaints) versus public ombudsmen, and better attuned to start-ups’ need…

This correctly represents my feelings about it.

Re: Facebook urged to make GDPR its “baseline standard” globally

#134

Earlier quoted context omitted.

thanks, wow responding to a letter like your first link could significantly bog down resources for a young company... you can imagine if you launched and even received moderate user growth early on, but then started receiving such letters, your productivity could go down the tubes.

I disagree. Here's an outline of what a response to the letter in that first link should look like for a small, well-meaning* startup: The letter is nicely formatted into 9 bullets. All are optional for small companies, and all can be automated - the answer should be the same for all users. 1. This is a "yes" or "no" question. If the answer is "no", you can ignore the rest of the letter. If yes, the answer is the sam…

> 3. You can avoid doing if you want. If you are doing this, you're signing up to take on this additional burden of informing your users. Consider this when making this decision. This is the only bullet in the list that is in any way burdensome as you will need to update this text in your automated response whenever you take on 3rd-parties (if at all).

Pretty much everyone is going to. Google Analytics, Zendesk, Salesforce, and more all qualify. Hell, even AWS qualifies...

> 5. and 6. are "if" conditionals that you shouldn't be doing. The answer should be "No".

Why do you say that? Given that we're discussing technical companies, I fully expect that automated decisions will be made.

> 7. Amounts to "has my data been hacked". If yes, that's unfortunate, but obviously you have a moral obligation to respond here regardless. Presuming you're hacked once, you provide full details once and send automatically to any users who ask.

And "detail all your security measures". Which, for a small company that doesn't have an InfoSec group, probably means next to nothing. An admission that feels a lot like liability...

> 8. and 9. are out of place. GDPR doesn't require you to respond to these questions within this quoted 1 month time limit (you do have to have what's detailed within them in place to comply with GDPR but that's tangential to info requests). These seem to have been put into this blog post as extra scaremongering.

It's the sort of thing an angry consumer might do, and most startup founders subject to GDPR are not deeply knowledgeable about it.

Re: Facebook urged to make GDPR its “baseline standard” globally

#135

Maybe it’s my American DNA but I don’t want European laws. I don’t suspect this to be a popular sentiment here.

I generally agree with your statement of not wanting European laws due to cultural differences, but America is in sore need of privacy laws for citizens. People will be rallied to oppose said laws for the exact reason of not wanting Euro-style laws passed, which IMO is a huge shame.

Re: Facebook urged to make GDPR its “baseline standard” globally

#136

Having worked on GDPR, it is unnecessarily harsh and in no way, shape or form would I support this standard going global. There are plenty of ways to make users data completely private without being ridiculously overreaching the way GDPR is. And having the sword of infinite lawsuits hanging over your head has and never will work, look at how ambulance chasers in the US have taken the most mundane laws and turned them…

If the industry didn't want what they're trying to spin as an "overreaching" standard like GDPR, maybe they shouldn't have spent so much time and effort seeing how far they could push their abuse of users' privacy.

Re: Facebook urged to make GDPR its “baseline standard” globally

#137

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

A lot of people don’t care about fire safety either (until their house is burning down) which is why we have regulations, building codes, mandatory sprinklers in offices, etc. I am starting to look at privacy like it should be treated as a public safety concern, since it’s invisible to people until it’s not.

> A lot of people don’t care about fire safety either (until their house is burning down) which is why we have regulations, building codes, mandatory sprinklers in offices, etc.

We don't have mandatory sprinklers in home offices and undeveloped land and buildings that are still under construction.

The problem with the equivalent distinction in software is that there is no clear point that software is "finished" like a building is. The architect doesn't come back and make changes a year after the occupants move into a building.

If there is no exception for new code still under testing then there is no way to test new code. But if there is, everyone will live their lives inside of it.

Re: Facebook urged to make GDPR its “baseline standard” globally

#138

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

I equate the events right now surrounding Facebook to Upton Sinclair's book "The Jungle", and GDPR being the privacy-analogue to the creation of the FDA.

The FDA makes the medical field hard to break into for startups, but for good reason. New medical devices need to go through rigorous verification and validation to show that they work as intended. If a company making pacemakers had the same "move fast and break things" attitude as most of SV seems to have, I might never trust medical companies again. As a consumer, I'm extremely content with the quality of pharmaceuticals and devices, and I wish I could trust Facebook or Google as much as I trust Medtronic or Philips Healthcare.

Re: Facebook urged to make GDPR its “baseline standard” globally

#139

“Urging” Facebook to do anything not in its commercial interest isn’t worth squat. Best case: another vague promise to be broken as soon as we forget. Facebook needs to be broken up and an American GDPR codified into law. If you care about this, pick up the phone and call your Congressperson and Senators.

America is too business friendly for that to ever happen.

Re: Facebook urged to make GDPR its “baseline standard” globally

#140

Earlier quoted context omitted.

thanks, wow responding to a letter like your first link could significantly bog down resources for a young company... you can imagine if you launched and even received moderate user growth early on, but then started receiving such letters, your productivity could go down the tubes.

Honestly, those questions should be pretty easy to answer especially if your company is small. If as a business you can’t answer these basic questions about the data you want to collect from me, I’m going to be hesitant to share it. People keep sharing that “nightmare letter” link but won’t point out which question gives them nightmares and why.

I'll point out which question gives me nightmares, as the founder of a EU startup:

- the requirement to have a DPO. Based on the requirements for the DPO, no one in the company can fill the role (conflict of interest), so we must hire an employee or consultant (expensive either way for a small startup)

- one month to respond. That's a lot of informations to collect the first time, and I might have other fires to put out (or I have to be pro-active and have a prepared respond, which has the take the place of something else important to do)

- the sheer amount of informations to collect. In the age of plug and play solutions, that's a LOT of things to audit (Mailchimp, AWS, GA, Heroku, various Wordpress plugins, logging solution I don't even remember the name, just to name a few)

- tracking every single PI of a user. If your systems are not built for this, it's going to be lengthy. If you were created before the GDPR, they are probably not.

- tracking down the usage of those PI may be complicated depending of the expected scope and usage you do (fortunately for me, there is no ad nor data resell, so really only the scope is the problem)

- some process asked for have a serious implication you should have some and do some sort of things. This is not feasible for a small startup.

It boils down to: it takes time, and time is something I'd rather use for something else, and it also requires to do things that have huge fixed cost that the size of a small company can't absorb (at least not until there is a ready-made solution).

I define small startup as startups with less than 20 employees, that might have received Seed funding but not more. Those points might not all be applicable to a new startup created with GDPR in mind.

Post reply on HN